build(deps): Bump actions/setup-go from df1a11710ed378b187f40c71eb3d6c08d82e7108 to d60b41a563a30eac31c3ec623e6ff0b3f16e1a06 #1588
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# Copyright Contributors to the L3AF Project. | |
# SPDX-License-Identifier: Apache-2.0 | |
# | |
# For documentation on the github environment, see | |
# https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners | |
# | |
# For documentation on the syntax of this file, see | |
# https://docs.github.com/en/actions/reference/workflow-syntax-for-github-actions | |
name: Scorecards | |
on: | |
push: | |
branches: [ main ] | |
pull_request: | |
branches: [ main ] | |
concurrency: | |
# Cancel any Scorecards workflow currently in progress for the same PR. | |
# Allow running concurrently with any other commits. | |
group: scorecards-${{ github.event.pull_request.number || github.sha }} | |
cancel-in-progress: true | |
# Declare default permissions as read only. | |
permissions: read-all | |
jobs: | |
analysis: | |
name: Scorecards analysis | |
runs-on: ubuntu-latest | |
permissions: | |
# Needed to upload the results to code-scanning dashboard. | |
security-events: write | |
id-token: write | |
actions: read | |
contents: read | |
steps: | |
- name: "Checkout code" | |
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 | |
with: | |
persist-credentials: false | |
- name: "Run analysis" | |
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0 | |
with: | |
results_file: results.sarif | |
results_format: sarif | |
# (Optional) "write" PAT token. Uncomment the `repo_token` line below if: | |
# - you want to enable the Branch-Protection check on a *public* repository, or | |
# - you are installing Scorecard on a *private* repository | |
# To create the PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-pat. | |
# repo_token: ${{ secrets.SCORECARD_TOKEN }} | |
# Public repositories: | |
# - Publish results to OpenSSF REST API for easy access by consumers | |
# - Allows the repository to include the Scorecard badge. | |
# - See https://github.com/ossf/scorecard-action#publishing-results. | |
# For private repositories: | |
# - `publish_results` will always be set to `false`, regardless | |
# of the value entered here. | |
publish_results: ${{ github.event_name != 'pull_request' }} | |
# Upload the results as artifacts (optional). | |
- name: "Upload artifact" | |
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 | |
with: | |
name: SARIF file | |
path: results.sarif | |
retention-days: 5 | |
# Upload the results to GitHub's code scanning dashboard so it will be visible | |
# at https://github.com/l3af-project/l3afd/security/code-scanning. | |
- name: "Upload to code-scanning" | |
uses: github/codeql-action/upload-sarif@294a9d92911152fe08befb9ec03e240add280cb3 | |
with: | |
sarif_file: results.sarif |